Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cxw-8v65-76vf

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

CSRF vulnerability in Jenkins promoted builds Plugin

Jenkins promoted builds Plugin 3.9 and earlier does not require POST requests for HTTP endpoints implementing promotion (regular, forced, and re-execute), resulting in cross-site request forgery (CSRF) vulnerabilities.

These vulnerabilities allow attackers to promote builds.

Jenkins promoted builds Plugin 3.9.1 requires POST requests for the affected HTTP endpoints.

A security hardening since Jenkins 2.287 and LTS 2.277.2 prevents exploitation of this vulnerability.

Пакеты

Наименование

org.jenkins-ci.plugins:promoted-builds

maven
Затронутые версииВерсия исправления

<= 3.9

3.9.1

EPSS

Процентиль: 85%
0.02526
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.

EPSS

Процентиль: 85%
0.02526
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352